Laws · GDPR ·art-28-par-3 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller. That contract or other legal act shall stipulate, in particular, that the processor:
How it connects
Cited by
- CJEU: national DPA may exercise powers over local establishment handling only
- CJEU: DPA may investigate complaints but cannot impose penalties outside its territory
- Guidelines 9/2022 on personal data breach notification under GDPR
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR
- Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)
All 68
- Kolibri Image Regina und Dirk Maass GbR: Insufficient data processing agreement
- Avata Hispania, S.L.: Insufficient legal basis for data processing
- Krajowa Szkoła Sądownictwa i Prokuratury: Insufficient technical and organisational measures to ensure information security
- Marbella Resorts S.L.: Insufficient data processing agreement
- Ferde AS: Non-compliance with general data processing principles
- One Way Private Company: Insufficient technical and organisational measures to ensure information security
- PIKA Sp. z o.o.: Insufficient technical and organisational measures to ensure information security
- Societatea Energetică Electrica S.A.: Insufficient data processing agreement
- PRINTAFORM Ltd.: Insufficient technical and organisational measures to ensure information security
- CITYSCOOT: Non-compliance with general data processing principles
- Bank: Insufficient technical and organisational measures to ensure information security
- Aid organization: Insufficient technical and organisational measures to ensure information security
- Debt collection agency: Insufficient technical and organisational measures to ensure information security
- HISPAPOST, S.A.: Insufficient fulfilment of data breach notification obligations
- POLAND DPA: Insufficient technical and organisational measures to ensure information security
- Hospital: Insufficient technical and organisational measures to ensure information security
- Hospital: Non-compliance with general data processing principles
- Covid 19 Test Lab: Insufficient technical and organisational measures to ensure information security
- Cooperativa Sociale Quadrifoglio: Insufficient technical and organisational measures to ensure information security
- Legal Person: Insufficient legal basis for data processing
- YUNEXPRESS SPAIN, S.L.: Insufficient data processing agreement
- EDPB Annual Report 2024
- Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation
- Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation
- Opinion 34/2025 on the draft decision of the Greek Supervisory Authority regarding C.E.C.L certification criteria
- Data Protection Commissioner v Facebook Ireland and Maximillian Schrems
- Unabhängiges Landeszentrum für Datenschutz v Wirtschaftsakademie Schleswig-Holstein
- Legal Entity: Insufficient data processing agreement
- Thessaloniki–Thessaly Gas Supply Company S.A.: Insufficient data processing agreement
- Ministero dell’Economia e delle Finanze: Insufficient legal basis for data processing
- Société Wallonne des Eaux: Insufficient legal basis for data processing
- Contribution of the EDPB to the European Commission’s evaluation of the Data Protection Law Enforcement Directive (‘‘LED’’) under Article 62 LED
- If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation
- Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security
- Generative AI and data protection
- NAIH: School grades are personal data; failure to provide access in eKRÉTA system
- Opinion 27/2024 on the Brand Compliance criteria of certification regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 (GDPR)
- Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)
- Opinion 11/2024 on the use of facial recognition to streamline airport passengers’ flow (compatibility with Articles 5(1)(e) and(f), 25 and 32 GDPR)
- Opinion 7/2024 on the draft decision of the German North Rhine Westphalia Supervisory Authority regarding the EU Cloud Service Data Protection (Auditor) certification criteria
- EDPB-EDPS Joint Opinion 01/2023 on the Proposal for a Regulation of the European Parliament and of the Council laying down additional procedural rules relating to the enforcement of Regulation (EU) 2016/679
- Recommendations 1/2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR)
- EDPB Annual Report 2022
- Opinion 25/2022 regarding the European Privacy Seal (EuroPriSe ) certification criteria for the certification of processing operations by processors
- EDPB Annual Report 2021
- Opinion 1/2022 on the draft decision of the Luxembourg Supervisory Authority regarding the GDPR – CARPA certification criteria
- Contribution of the EDPB to the European Commission’s evaluation of the Data Protection Law Enforcement Directive (LED) under Article 62
- Opinion 18/2021 on the draft Standard Contractual Clauses submitted by the LT SA (Article 28(8) GDPR)
- EDPB-EDPS Joint Opinion 1/2021 on standard contractual clauses between controllers and processors
- Opinion 30/2020 on the draft decision of the competent supervisory authority of Austria regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)
- Opinion 17/2020 on the draft Standard Contractual Clauses submitted by the SI SA (Article 28(8) GDPR)
- Opinion 14/2019 on the draft Standard Contractual Clauses submitted by the DK SA (Article 28(8) GDPR)
- Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR)
- Criminal proceedings against HP
- UODO (Poland) - DKN.5131.5.2025
- IP (Slovenia) - 0609-41/2026/7
- AEPD: Ramona Films failed to comply with Article 58(2) order to provide processor
- HDPA (Greece) - 15/2026
- Pianeta S.r.l.: Non-compliance with general data processing principles
- HDPA investigates Greek Infrastructure Ministry for SMS sent without consent or
- AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight
- Land-surveying office: Insufficient technical and organisational measures to ensure information security
- Unknown legal entity: Insufficient data processing agreement
Related across sources
14/2021 Cypriot court backs DPA fines of €40,000 each on football clubs and €25,000 on processor On 26 July 2021, a journalist informed the Cypriot DPA of a security vulnerability on an online platform. This online platform hosted ticket purchase sites of two Cypriot football… Administrative Court of Cyprus May 12, 2026 Controllers Processors Supervisory Authorities
Opinion 22/2024 certain obligations following from the reliance on processor(s) and sub-processor(s) A dopted 1 Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub - processor(s) Adopted on 7 October 2024 Adopted 2 Executive summary The… Opinion ·EDPB Oct 9, 2024 Processors Controllers Processing Agreement
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Jul 7, 2021 Controllers Processors IP Address
S 5 SF 65/24 DS SG Nürnberg: MOVEit zero-day cyberattack via processor did not breach Art. 32 GDPR The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus… Social Court Nuremberg Jun 10, 2026 Processors Controllers Integrity and Confidentiality Principle
Guidelines 8/2022 identifying a controller or processor's lead supervisory authority Guidelines for identifying a controller or processor’s lead supervisory authority Guidelines ·EDPB Apr 17, 2023 Supervision Controllers Supervisory Authorities
€750,000 AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight Vodafone España, S.A.U., the controller, operated a service known as "Super WiFi" through a third-party processor. Following a data breach affecting the service, the DPA's… Spain ·Art. 5, 28, 32 Sep 23, 2026 Processors Controllers Processing Agreement